Next | Query returned 77 messages, browsing 51 to 60 | Previous

History of commit frequency

CVS Commit History:


   2020-04-12 10:29:21 by Adam Ciarcinski | Files touched by this commit (956) | Package updated
Log message:
Recursive revision bump after textproc/icu update
   2020-04-10 12:41:50 by Nia Alarie | Files touched by this commit (2)
Log message:
firefox68: Update to 68.7.0

Security Vulnerabilities fixed in Firefox ESR 68.7

    #CVE-2020-6828: Preference overwrite via crafted Intent from malicious
    Android application

    #CVE-2020-6827: Custom Tabs in Firefox for Android could have the URI
    spoofed

    #CVE-2020-6821: Uninitialized memory could be read when using the WebGL
    copyTexSubImage method

    #CVE-2020-6822: Out of bounds write in GMPDecodeData when processing large
    images

    #CVE-2020-6825: Memory safety bugs fixed in Firefox 75 and Firefox ESR 68.7
   2020-04-04 17:26:42 by Nia Alarie | Files touched by this commit (2)
Log message:
firefox68: Update to 68.6.1

Security Vulnerabilities fixed in Firefox 74.0.1 and Firefox ESR 68.6.1

    #CVE-2020-6819: Use-after-free while running the nsDocShell destructor
    #CVE-2020-6820: Use-after-free when handling a ReadableStream
   2020-03-30 21:46:03 by Joerg Sonnenberger | Files touched by this commit (22)
Log message:
Fix build with libc++ by making the template wrapper do what it is
supposed to do. Don't mess with math.h internals. Honor ressource limit
changes during build.
   2020-03-18 02:33:58 by David H. Gutteridge | Files touched by this commit (1)
Log message:
firefox68: remove stale and now redundant override
   2020-03-12 20:39:35 by Nia Alarie | Files touched by this commit (13)
Log message:
firefox68: Update to 68.6.0

While here,

- Remove OSS support now that cubeb_sun has been stable for a long while
- Appease pkglint

Security fixes in this release:

#CVE-2020-6805: Use-after-free when removing data about origins
#CVE-2020-6806: BodyStream::OnInputStreamReady was missing protections
#CVE-2020-6807: Use-after-free in cubeb during stream destruction
#CVE-2020-6811: Devtools' 'Copy as cURL' feature did not fully escape
#CVE-2019-20503: Out of bounds reads in sctp_load_addresses_from_init
#CVE-2020-6812: The names of AirPods with personally identifiable
#CVE-2020-6814: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6
   2020-03-10 23:11:24 by Thomas Klausner | Files touched by this commit (1681) | Package updated
Log message:
librsvg: update bl3.mk to remove libcroco in rust case

recursive bump for the dependency change
   2020-03-08 17:42:31 by Benny Siegert | Files touched by this commit (67)
Log message:
Revbump packages depending on libffi after .so version change.

Requested by Matthias Ferdinand and Oskar on pkgsrc-users.
   2020-02-27 12:06:30 by Nia Alarie | Files touched by this commit (1)
Log message:
firefox68: Fix some pkglint warnings
   2020-02-15 13:48:22 by Nia Alarie | Files touched by this commit (3)
Log message:
firefox68: Update to 68.5.0

Security Vulnerabilities fixed in Firefox ESR68.5

# CVE-2020-6796: Missing bounds check on shared memory read in the parent process
# CVE-2020-6797: Extensions granted downloads.open permission could open \ 
arbitrary applications on Mac OSX
# CVE-2020-6798: Incorrect parsing of template tag could result in JavaScript \ 
injection
# CVE-2020-6799: Arbitrary code execution when opening pdf links from other \ 
applications, when Firefox is configured as default pdf reader
	Note: This issue only affects Windows operating systems and when Firefox is \ 
configured as the default handler for non-default filetypes. Other operating \ 
systems are unaffected.
# CVE-2020-6800: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5

Next | Query returned 77 messages, browsing 51 to 60 | Previous